Site navigation

Scot-Secure 2018: Culture, Communication and Back to Basics

Dominique Adams

,

ScotSecure 2018

Now entering its fourth year DIGIT’s annual cyber security conference attracted an array of outstanding cyber security experts to share their industry insights and case studies with 300 plus attendees at Edinburgh’s Dynamic Earth.

Supported by ScotlandIS, Police Scotland, SBRC, The Cyber Academy and ISACA, ScotSecure 2018’s programme focused on supporting cybersecurity best-practice, identifying key cyber threats and on offering practical advice on how to improve cyber resilience. Speakers also offered guidelines on how to implement effective security measures and how to foster a cyber aware corporate culture.

Across the 12 topics and four sessions of the event it became clear that the main message was that many companies and organisations persistently fail to employ basic cyber defence measures: essentially leaving the electronic door open to cyber criminals. We also learned that there are two types of companies: those who have already suffered a data breach and those who do not yet realise it’s already happened.

As hackers evolve and become more sophisticated it is becoming more unlikely firms will be able to avoid cyber attacks. Another prevalent theme was the need to educate and implement a good cyber aware culture across the entire organisation, to truly reduce future risks. SCOE SECURE 2018 SPEAKERS

Greater Understanding and Dialogue Needed

DI Nicola Burnett of Police Scotland explained that cybercrime is rapidly evolving, it has become more sophisticated and easier to commit. Technology has enabled criminals, who ten years ago were pilfering shops, to take their crime online. Burnett noted that it is not just low-level criminals engaging in it but also organised crime groups. She urged that the perception of malicious cyber behaviour be changed emphasising that cyber-crime is still crime in the eyes of the law. Burnett predicted that there will be an increase in victims of cyber-crime, saying that already more than £2 million has been lost to it. By encouraging good cyber hygiene, educating the public about being safe online and collaborating to share data the police will be able to form effective digital strategies.

How Companies Fail the Basics

Hackers prefer the route of least resistance and by failing to implement and update basic cyber security measures companies are exposing their data. A weak cyber defence foundation is where most firms stumble. Ed Tucker, CIO of DP Governance said: “Getting all the basics wrong leaves us wide open and we end up chasing false positives. Attacks don’t need to be sophisticated to target poorly defended businesses.”

Frederico Charosky MD of Quorum Cyber emphasised that throwing cash at the problem would not necessarily mean greater safety, instead he urged companies to work on personalised risk reduction. A cookie-cutter cyber security model is not the path to take, as it can prove ineffective and far more expensive.

Companies are often so busy chasing cybersecurity auditors, they can neglect the real threat. By focusing on an effective, focused strategy, ticking all the audit boxes becomes a by-product. It is easy to get caught up in the frameworks, but you risk missing the bigger picture and the actual threats you are facing.

Cyber Security is Everyone’s Business

The lack of communication, integration and awareness between users, IT and the boardroom mean that you are leaving value on the table and putting your data at risk. Tucker said: “Every cyber attack starts with a human being,” which is why users need to be educated to defend their own personal data and cyber presence, an awareness which they will then bring back to the organisation. Most breaches are not due to futuristic AI or slick hackers, it is because someone has used a weak password or an outdated version of Java.

Lisa Forte, former intelligence officer and police cybercrime investigator now Partner at Red Goat Cyber Security explained that many incidents are due to social engineering methods such as; phising (using email to get access to sensitive data), vishing (via telephone), impersonation, trust attacks and smishing (using SMS). However, by educating employees about these techniques you can decrease the risk of an accidental data leak due to human error. Basically put, if your users are not safety aware then you are failing at your job.

How to Up Your Cyber Defence Strategy

Cybersecurity needs to be integrated into your business strategy and corporate culture, it cannot be an add on project. There needs to be a more holistic approach to creating a cybersecurity it must be in line with what the business is trying to achieve and agile. Kate Goldman, Director at KBG Solutions said that without good cyber aware culture or business engagement it is like creating a strong door and leaving keys all over the place.

Cyber experts need to learn the language of business, as Jordan Schroeder CIO and Managing CISO at UCSS said: “We need to spend less time as Batman (cyber expert) and more time as Bruce Wayne in a three-piece suit talking to businesses.” The cyber side needs to speak to and ask questions about the business, so they can accurately shape risk and offer the best solutions.

Rather than telling a business what it should do, cyber security teams needs to inspire businesses to take action instead. Another good strategy is to map out the flow of your information within your business, this will help direct how to put the right controls in place, identify the legal challenges and assist in detecting and tracking a breach.

 

 

Dominique Profile Picture

Dominique Adams

Marketing Content Manager, Trickle

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data